CVE-2022-24630 | AudioCodes Device Manager Express up to 7.8.20002.47752 POST Request BrowseFiles.php ssh_command command injection (EDB-51145)
A vulnerability has been found in AudioCodes Device Manager Express up to 7.8.20002.47752 and classified as critical. Affected by this vulnerability is an unknown functionality of the file BrowseFiles.php of the component POST Request Handler. The manipulation of the argument ssh_command leads to command injection.
This vulnerability is known as CVE-2022-24630. The attack can only be done within the local network. Furthermore, there is an exploit available.